Security
Security & trust
These are implementation controls, not certifications. Every claim below is backed by code in the tree.
Tenant isolation
Tenant data is separated by PostgreSQL row-level security. The app connects as the low-privilege lastinspected_app role, and the database policies namedtenant_isolation enforce each tenant’s boundary.
Credentials
Account passwords are hashed with bcrypt before storage. The application does not store a recoverable password value.
Uploads
Uploaded photos and signatures are content-addressed by their own hash. The storage layer verifies file type from magic bytes, accepts only JPEG, PNG, WEBP, and PDF where appropriate, and excludes SVG.
Audit trail
The audit ledger is append-only. Database triggers block UPDATE and DELETE onaudit_events, so history is recorded, not rewritten.
Tenant erasure
The product has a tenant erasure workflow for deletion requests. It removes the tenant and its tenant-scoped rows, then cleans up orphaned blobs.
Related policies
See our Privacy Policy, Terms of Service, and Subprocessors.